CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,071 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-04
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-11522 EXP | Yosoro 1.0.4 has stored XSS. | Patch early | 6.1 medium | 4.3% | 2018-06-02 |
| CVE-2012-4231 EXP | Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 4.3% | 2012-10-22 |
| CVE-2007-3182 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arb… | Patch early | 4.3 medium | 4.3% | 2007-06-26 |
| CVE-2008-6978 EXP | Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with a… | Patch early | 6.8 medium | 4.3% | 2009-08-19 |
| CVE-2000-0984 EXP | The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. | Patch early | 5.0 medium | 4.3% | 2000-12-19 |
| CVE-2006-3259 EXP | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep paramet… | Patch early | 4.3 medium | 4.3% | 2006-06-27 |
| CVE-2012-5876 EXP | Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (cras… | Patch early | 5.0 medium | 4.3% | 2014-05-30 |
| CVE-2011-4958 EXP | Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote at… | Patch early | 4.3 medium | 4.3% | 2014-04-08 |
| CVE-2006-5210 EXP | Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FI… | Patch early | 5.0 medium | 4.3% | 2006-10-16 |
| CVE-2004-2099 EXP | Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary cod… | Patch early | 5.1 medium | 4.3% | 2004-12-31 |
| CVE-2011-5049 EXP | MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port… | Patch early | 4.3 medium | 4.3% | 2012-01-04 |
| CVE-2003-1368 EXP | Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | Patch early | 6.4 medium | 4.3% | 2003-12-31 |
| CVE-2008-1467 EXP | CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "receive… | Patch early | 6.8 medium | 4.3% | 2008-03-24 |
| CVE-2016-5740 EXP | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Ma… | Patch early | 6.1 medium | 4.3% | 2016-12-15 |
| CVE-2002-1480 EXP | Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which i… | Patch early | 6.8 medium | 4.3% | 2003-04-22 |
| CVE-2017-2445 EXP | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issu… | Patch early | 6.1 medium | 4.3% | 2017-04-02 |
| CVE-2017-8684 EXP | Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows… | Patch early | 5.5 medium | 4.3% | 2017-09-13 |
| CVE-2012-5858 EXP | Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitr… | Patch early | 4.3 medium | 4.3% | 2012-12-03 |
| CVE-2004-1196 EXP | Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao par… | Patch early | 6.8 medium | 4.3% | 2005-01-10 |
| CVE-2014-0868 EXP | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which a… | Patch early | 4.9 medium | 4.3% | 2014-07-07 |
| CVE-2015-1058 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[C… | Patch early | 4.3 medium | 4.3% | 2015-01-16 |
| CVE-2003-0416 EXP | Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year para… | Patch early | 6.8 medium | 4.3% | 2003-06-30 |
| CVE-2003-0492 EXP | Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via… | Patch early | 6.8 medium | 4.3% | 2003-08-07 |
| CVE-2006-6962 EXP | PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to ex… | Patch early | 6.8 medium | 4.3% | 2007-01-29 |
| CVE-2002-1708 EXP | Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting scrip… | Patch early | 6.8 medium | 4.3% | 2002-12-31 |
| CVE-2002-1727 EXP | Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbi… | Patch early | 6.8 medium | 4.3% | 2002-12-31 |
| CVE-2003-1516 EXP | The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violate… | Patch early | 6.8 medium | 4.3% | 2003-12-31 |
| CVE-1999-0986 EXP | The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. | Patch early | 5.0 medium | 4.3% | 1999-12-08 |
| CVE-2008-7061 EXP | The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remo… | Patch early | 4.3 medium | 4.3% | 2009-08-24 |
| CVE-2007-6367 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 4.3% | 2007-12-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt